07 Oct
|
38North Security
|
Australia
07 Oct
38North Security
Australia
About 38North
38North Security is a US-headquartered, global cloud security advisory and engineering firm helping organisations build, assess and operate secure, compliant cloud environments. Our clients range from innovative start-ups to Fortune 500 companies, including cloud service providers, security vendors and organisations serving government, healthcare and other highly regulated markets. We support security standards and regulatory requirements across North America, the United Kingdom, continental Europe and Asia-Pacific, including Australia and Japan.
Our teams support the full security and compliance lifecycle - from strategy, readiness reviews and independent assessments to secure cloud architecture, hands-on engineering and ongoing operational support. We help clients enter regulated markets, strengthen their security capabilities and meet multiple frameworks without unnecessarily duplicating effort. Our expertise spans Australian requirements such as IRAP/ISM, Essential Eight and DISP, alongside international frameworks including FedRAMP, CMMC, ISMAP, ISO 27001 and SOC 2.
NorthWatch, our continuous assurance platform, complements these services by bringing together security telemetry, automated evidence, continuous validation and compliance operations.
As we expand our APAC footprint, we’re offering Australian practitioners the opportunity to build an international security career from Australia. You’ll work with global technology companies, collaborate with experienced international specialists and broaden your experience across different regulatory environments. This is an opportunity to bring your Australian security expertise to global engagements, deepen your technical and advisory skills, and help shape the growth of our regional capabilities.
Location
Remote but must be resident in Australia (Canberra or Sydney preferred).
Occasional domestic and international travel may be required. Regular early-morning or early-evening availability is needed to collaborate with US-based clients and colleagues.
About the Role
We’re seeking an ASD-endorsed IRAP assessor to lead Australian security advisory and assessment engagements. You will conduct IRAP assessments, advise on ISM implementation, assess Essential Eight maturity and support Defence Industry Security Program (DISP) readiness. IRAP assessments will be conducted only on systems where 38North has had no advisory or documentation role, preserving assessment independence.
This is a consulting-to-permanent opportunity. You will begin as an independent consultant, with the intention of transitioning promptly to permanent employment. We’re looking for candidates seeking a long-term role with 38North, with the transition timeframe and employment terms agreed during recruitment.
Responsibilities
- Lead IRAP assessments of cloud services at the PROTECTED level, producing clear, evidence-based findings and reports.
- Deliver ISM readiness reviews, Essential Eight maturity assessments and DISP readiness/gap assessments, providing practical implementation advice and prioritized remediation roadmaps.
- Develop and review security documentation, risk assessments, operational plans and assessment evidence.
- Advise on cloud architecture, assessment boundaries, data sovereignty, identity, privileged access, logging, cryptography and shared responsibilities.
- Map existing FedRAMP, ISO 27001 and SOC 2 evidence to Australian requirements, identifying gaps and opportunities for reuse.
- Manage client engagements across time zones, maintaining responsive communication, assessment quality, confidentiality and independence.
- Contribute to proposals, methodologies, training and the growth of our APAC capabilities.
Qualifications
- Current ASD endorsement as an IRAP assessor is required.
- Australian citizenship and an active NV1 security clearance or higher.
- At least eight years of ICT security experience, including four years assessing or implementing ISM controls for Australian Government or government-facing systems.
- Demonstrated delivery of cloud IRAP assessments or ISM readiness engagements at PROTECTED, with practical experience in AWS, Microsoft Azure or Google Cloud.
- Solid knowledge of the ISM, IRAP assessment requirements and Protective Security Policy Framework (PSPF), with the capability to advise on and assess Essential Eight maturity and DISP readiness.
- Excellent report writing, client communication and independent engagement management, supported by sound technical judgement.
- At least one relevant certification: CISSP, CISM, CISA, CRISC or ISO/IEC 27001 Lead Auditor.
- An ABN and the ability to invoice during the initial consulting period, together with an interest in transitioning promptly to permanent employment.
Optional (Nice to Have Requirements)
- AWS, Azure or Google Cloud certifications.
- Experience with FedRAMP, CMMC, ISO 27001, SOC 2 or other international security frameworks.
- Familiarity with the Hosting Certification Framework and Security of Critical Infrastructure obligations.
- Experience with infrastructure as code, security automation, continuous assurance or GRC/evidence platforms.
📌 IRAP Assessor / Senior IRAP Advisor (Australia)
🏢 38North Security
📍 Australia